Zend Framework before 2.4.9, zend-framework/zend-crypt 2.4.x before 2.4.9, and 2.5.x before 2.5.2 allows remote attackers to recover the RSA private key.
Weaknesses in this category are related to errors in the management of cryptographic keys.
Link | Tags |
---|---|
https://framework.zend.com/security/advisory/ZF2015-10 | vendor advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=1283137 | issue tracking third party advisory |